The Federal Bureau of Investigation is warning consumers about a caller-ID spoofing scheme that impersonates banks, and even the bureau itself, to trick people into wiring or transferring money out of their own accounts. The warning centers on a category the FBI already tracks closely: phishing and spoofing complaints, which the bureau’s Internet Crime Complaint Center says produced more than $215 million in reported losses over a single year. The scam’s mechanics are simple, but its scale, and its reliance on a caller’s own trust in a familiar-looking phone number, have made it one of the more difficult scams for banks and regulators to stop.
How A Spoofed Number Empties An Account
The scheme relies on a technology called caller-ID spoofing, which lets a scammer make an incoming call display the name and number of a real institution, such as a bank or even a law-enforcement agency, even though the call originates somewhere else entirely. Consumers targeted by the scheme have reported callers impersonating major banks, including Chase and Huntington, as well as callers claiming to be from the FBI itself, according to reporting on the FBI’s warning. The caller typically tells the victim that the person’s account has been compromised or that fraudulent activity has been detected, creating urgency and confusion, then instructs the victim to move funds into a different account, often through a peer-to-peer payment service such as Zelle, to keep the money ‘safe.’ Once the transfer is made, the money is effectively gone, since it was sent willingly by the account holder, even if under false pretenses.
What The FBI’s Own 2025 Numbers Show
The bureau’s Internet Crime Complaint Center, known as IC3, logged just over 1 million complaints in 2025, up from roughly 859,500 the year before, contributing to nearly $21 billion in reported losses from cyber-enabled crime for the year, according to the center’s 2025 Internet Crime Report. Within that total, phishing and spoofing complaints, the category that covers this kind of impersonation scheme, were among the most frequently reported types the center received, totaling 191,561 reports and combined losses of just over $215 million. The one-year jump in complaint volume continued a multi-year climb in reported cybercrime that the bureau has tracked for years through its annual report. That figure covers a broad range of impersonation attempts, not solely the bank-spoofing scheme making headlines, but banking, government, and law-enforcement impersonation are consistently among the most common variations reported to the center, which operates as the FBI’s central clearinghouse for internet and cyber-enabled crime complaints, described in more detail on the bureau’s own IC3 website.
Banks Say They Will Never Ask For This
Financial institutions caught up in the spoofing wave have issued near-identical guidance in response. Chase has urged customers to ignore phone, text, or internet requests to move money or grant access to a computer or bank account, noting that legitimate companies do not make those requests. Huntington Bank has said it may occasionally contact customers but will never ask for login credentials, passwords, two-factor authentication codes, or ask a customer to install software to ‘secure’ an account. Both banks recommend hanging up immediately on any unexpected call and redialing using the number printed on the back of a debit or credit card, rather than calling back a number provided by the suspicious caller.
The Inspector General’s Red Flags
The Federal Deposit Insurance Corporation’s Office of Inspector General has published its own guidance on the pattern, flagging a false sense of urgency and a request for sensitive personal or account information as the two most reliable warning signs of a spoofed call. Banks, companies, and government agencies, the inspector general’s office notes, do not call or send unsolicited messages asking for sensitive personal information. Consumers are advised to treat every incoming call as potentially suspicious, even one that appears to come from a recognized number, to never provide account numbers, passwords, or one-time verification codes to an unsolicited caller, and to independently look up an institution’s phone number rather than trust a number supplied during the call itself.
A Scam That Outruns Caller ID
What makes the scheme especially hard to stop is that it does not rely on hacking a bank’s systems or breaching a victim’s phone; it exploits the basic trust built into how caller ID works. Investigators have found that scammers frequently supplement a spoofed number with personal details, such as an account balance or a partial account number, obtained from data breaches or discarded documents, which makes the call sound far more credible than a generic scam attempt. Because the money is transferred by the account holder rather than stolen outright through a hack, banks and regulators have said it is often difficult to recover funds once a transfer has gone through, which is why federal guidance leans so heavily on prevention rather than after-the-fact recovery. The bureau has issued similar caller-impersonation warnings in prior years under different names, including alerts about scammers posing as tech-support staff or bank fraud departments, and each new advisory tends to repeat the same core advice: hang up, verify independently, and never move money on a caller’s instructions alone.
This article was produced with the assistance of AI and reviewed by Morning Overview editors.
More from Morning Overview